# Exploit Title:  Design & Hosting by Mando Hosting / SQL Injection Vulnerability
#-----------------------------------------------------------------------------------------
# Exploit Author:  Mehdi Razmjoo ( razmjumehdi@gmail.com )
#-----------------------------------------------------------------------------------------
# Date: 2018.4.10
#-----------------------------------------------------------------------------------------
# Vendor Homepage: http://www.hostmando.com
#-----------------------------------------------------------------------------------------
# CWE:  CWE-89
#-----------------------------------------------------------------------------------------
# Category: Web Application
#-----------------------------------------------------------------------------------------
#Dork: -
#-----------------------------------------------------------------------------------------
# Vulnerability Path:   http://Server/gallery.php?cat=Hogsback
#-----------------------------------------------------------------------------------------
#Tested On:  Kali Linux ( Firefox )
#-----------------------------------------------------------------------------------------
# Description:
#
# The vulnerability allows an attacker to inject sql commands. An bad guy might injects commands on URL in this 
# path:
#
# http://www.amatolatrails.co.za/gallery.php?cat=Hogsback
#
#-----------------------------------------------------------------------------------------
#